Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2026-01-14 12:26:12 2026-01-14 10:52:34 2026-01-14 10:52:29 9547018

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

17 hours ago • •

daniel:// stenberg://

17 hours ago • •


We are at *twenty* hackerone submissions for #curl so far this year. Zero of them a confirmed vulnerability.
#curl
This entry was edited (17 hours ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Lars Marowsky-Brée 😷
mastodon - Link to source

Lars Marowsky-Brée 😷

in reply to daniel:// stenberg:// • 17 hours ago • •
Shld I submit a #hackerone submission for #curl, identifying hackerone as a DoS attack vector for the project, recommending depreciation?
#curl #hackerone
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Edvin Malinovskis
mastodon - Link to source

Edvin Malinovskis

in reply to daniel:// stenberg:// • 16 hours ago • •
was there at least one "could be seen as a bug if you squint hard enough"?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Edvin Malinovskis

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Edvin Malinovskis • 15 hours ago • •
yes, several of them were bugs in fact
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

JP Mens
mastodon - Link to source

JP Mens

in reply to daniel:// stenberg:// • 15 hours ago • •
that screams for a new graph: "average number of hackerone submissions to the curl project per day". :)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to JP Mens

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to JP Mens • 15 hours ago • •
I foolishly thought *per year* would be the appropriate time frame: curl.se/dashboard1.html#hacker… (the graph hasn't updated yet)

curl - Project status dashboard

curl.se
This entry was edited (15 hours ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Volker Stolz
mastodon - Link to source

Volker Stolz

in reply to daniel:// stenberg:// • 15 hours ago • •

Wasn’t 📈exponential growth📈 what every project was hoping to achieve?!

Maybe it should be mandatory that the HackerOne submission must be done with `curl -X PUT … `, including BearerTokens/OAuth etc?

  •  Languages
  •  Search Text
  •  Share via ...
⇧